# Tessera — security contact information (RFC 9116) # # TODO before launch: replace every PLACEHOLDER_DOMAIN value, publish the PGP # key at the referenced URL, and set Expires to a date less than one year out. # An expired security.txt is worse than no security.txt. Contact: mailto:security@PLACEHOLDER_DOMAIN.example Contact: https://PLACEHOLDER_DOMAIN.example/security/disclosure Expires: PLACEHOLDER_ISO8601_EXPIRY Encryption: https://PLACEHOLDER_DOMAIN.example/.well-known/pgp-key.txt Policy: https://PLACEHOLDER_DOMAIN.example/security/disclosure Preferred-Languages: en Canonical: https://PLACEHOLDER_DOMAIN.example/.well-known/security.txt # We aim to acknowledge all reports within five business days and follow a # 90-day coordinated disclosure timeline. Good-faith research conducted within # our published policy is authorised; see the Policy link above for safe # harbour terms and scope.